Re: Trust relationship between this workstation and the primary do



I'm still having the same issue when I first posted.
I cant add a new domain user account at a workstation.
I included the orig post below.

I only have one DC/DNS server

I only had one problem (at least that was causing issues) which I included
below. The only actual change I made was to remove a gateway entry from the
DC/DNS server from the NIC config. It was there as a test from trying to get
communications setup with a remote subnet via a T1. That's not there now.
Everything else was working fine anyway for many months with that entry there.


Thanks!

===========================================
Orig post stating problem:

When I try to add a new user account at a workstation previously joined to a
domain, I get an error saying I can't add the user because

"the trust relationship between this workstation and the primary domain
failed ".

I tried removing the computer object from AD & re-joining but that didn't
help. This is ocurring on stations that are working fine otherwise. The
only problem is adding a new user account on the station. Existing accounts
on the stations are working fine. If I add an existing account to a
different station, same result. Tried setting up a new account in AD. Same
error when adding account to station.


===========================================
DC-DCDiag:

DC Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial non skippeable tests

Testing server: Default-First-Site-Name\HHWPNT1
Starting test: Connectivity
......................... HHWPNT1 passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\HHWPNT1
Starting test: Replications
......................... HHWPNT1 passed test Replications
Starting test: Topology
......................... HHWPNT1 passed test Topology
Starting test: CutoffServers
......................... HHWPNT1 passed test CutoffServers
Starting test: NCSecDesc
......................... HHWPNT1 passed test NCSecDesc
Starting test: NetLogons
......................... HHWPNT1 passed test NetLogons
Starting test: Advertising
......................... HHWPNT1 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... HHWPNT1 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... HHWPNT1 passed test RidManager
Starting test: MachineAccount
......................... HHWPNT1 passed test MachineAccount
Starting test: Services
Could not open IISADMIN Service on [HHWPNT1]:failed with 1060:
The specified service does not exist as an installed service.
Could not open SMTPSVC Service on [HHWPNT1]:failed with 1060:
The specified service does not exist as an installed service.
......................... HHWPNT1 failed test Services
Starting test: OutboundSecureChannels
** Did not run Outbound Secure Channels test
because /testdomain: was not entered
......................... HHWPNT1 passed test OutboundSecureChannels
Starting test: ObjectsReplicated
......................... HHWPNT1 passed test ObjectsReplicated
Starting test: frssysvol
......................... HHWPNT1 passed test frssysvol
Starting test: kccevent
......................... HHWPNT1 passed test kccevent
Starting test: systemlog
An Error Event occured. EventID: 0x00000457
Time Generated: 02/01/2007 09:55:51
Event String: Driver Microsoft Shared Fax Driver required for

An Error Event occured. EventID: 0x00000452
Time Generated: 02/01/2007 09:55:51
Event String: The printer could not be installed.
An Error Event occured. EventID: 0x00000457
Time Generated: 02/01/2007 09:55:51
Event String: Driver

An Error Event occured. EventID: 0x00000452
Time Generated: 02/01/2007 09:55:51
Event String: The printer could not be installed.
An Error Event occured. EventID: 0x00000457
Time Generated: 02/01/2007 09:55:51
Event String: Driver hp psc 2100 series required for printer

An Error Event occured. EventID: 0x00000452
Time Generated: 02/01/2007 09:55:51
Event String: The printer could not be installed.
......................... HHWPNT1 failed test systemlog

Running enterprise tests on : hhwpcac.org
Starting test: Intersite
......................... hhwpcac.org passed test Intersite
Starting test: FsmoCheck
......................... hhwpcac.org passed test FsmoCheck


===========================================
DC-IPConfig:

Windows 2000 IP Configuration
Host Name . . . . . . . . . . . . : hhwpnt1
Primary DNS Suffix . . . . . . . : hhwpcac.org
Node Type . . . . . . . . . . . . : Broadcast
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : hhwpcac.org

Ethernet adapter Local Area Connection 5:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Linksys EG1032 v2 Instant Gigabit
Network Adapter #3
Physical Address. . . . . . . . . : 00-0C-41-EB-CB-13
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 172.20.100.2
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . : 172.20.100.200
DNS Servers . . . . . . . . . . . : 172.20.100.2

===========================================
Workstation IPConfig:

Windows 2000 IP Configuration
Host Name . . . . . . . . . . . . : MIPTemporary
Primary DNS Suffix . . . . . . . : hhwpcac.org
Node Type . . . . . . . . . . . . : Broadcast
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : hhwpcac.org
Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Linksys LNE100TX Fast Ethernet
Adapter(LNE100TX v4)
Physical Address. . . . . . . . . : 00-03-6D-18-1C-76
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 172.20.32.3
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . : 172.20.100.200
DNS Servers . . . . . . . . . . . : 172.20.100.2
===========================================


"Herb Martin" wrote:


"Server Guy" <ServerGuy@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:15C3AA06-EFDA-4C8D-92F4-AEA35B2CC203@xxxxxxxxxxxxxxxx
Hi, Yes, the same problem is still there. Still get the trust error when
trying to add a domain user to the station.

Which problem? (You have had several by now.)

What specifically are the current symptoms since after changing various
things you might have different, but still even similar issues.

One odd thing is when I look at the logs from netdiag & dcdiag, they show
1-1-1985 as the file creation & modify dates. Dates on DC and all servers
show correct time. Dont know if that is relevant or not but wanted to
mention it in-case something is calculating wrong because of some invalid
date.

Show us your CURRENT, UNEDITED text output from "ipconfig /all" of the
problem DC and the CURRENT, UNEDITED text output from "DCDiag /c"
for the problem DC.

Nice to have the same from a working DC also.

If you have "client problems" then CURRENT, UNEDITED text output
from "IPConfig /all" of the client.




.



Relevant Pages

  • Re: Re-Post - "the trust relationship between this workstation and
    ... account is NEW to the workstation. ... needs admin group priv at workstation level. ... only problem is adding a new user account on the station. ... This would be on the DNS server 172.20.100.2 ...
    (microsoft.public.windows.server.active_directory)
  • Re: is it best to migrate from NT4 server or start over?
    ... log into the new domain with the new user account (could be the ... domain only local workstation accounts will be available. ... When you revert to a "workgroup" after leaving the NT domain, ...
    (microsoft.public.windows.server.setup)
  • Re: NT authentication from a local windows NT 4.0 Wks to a NT Server 4.0
    ... workstation is logged into locally, ... The security on this account is local, ... or server), it checks your information versus its user database. ... Domain user database is the same as the local user database for those ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Trust relationship between this workstation and the primary do
    ... The following is the result of the NLtest from the affected workstation. ... Reset the computer account in AD, then re-add it to the domain. ... When I try to add a new user account at a workstation previously joined ... only problem is adding a new user account on the station. ...
    (microsoft.public.windows.server.active_directory)
  • Re: is it best to migrate from NT4 server or start over?
    ... log into the new domain with the new user account (could be the ... domain only local workstation accounts will be available. ... When you revert to a "workgroup" after leaving the NT domain, ...
    (microsoft.public.windows.server.setup)